Databricks-DA-Assoc Securing Data Practice Question
A data analyst is using a Databricks SQL warehouse to query a table that is protected by row-level security using dynamic views in Unity Catalog. The analyst has SELECT on the view but not on the underlying table. When querying the view, the analyst receives an error about insufficient privileges on the base table. What is the most likely cause?
⚠ Common exam trap
The trap here is assuming that the querying user needs direct privileges on the base table, when in fact the view owner's privileges are what matter.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The view owner does not have SELECT privilege on the underlying table, so the view cannot access it.
In Unity Catalog, views execute with the permissions of the view owner, not the querying user. If the view owner lacks SELECT on the underlying table, the view cannot access the data, resulting in a permission error for any user. The analyst's privileges on the view are sufficient, but the owner must have the necessary privileges on the base table.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The analyst needs to be granted SELECT on the base table directly to query the view.
Why it's wrong here
Granting SELECT on the base table is not required if the view owner has the necessary privileges. The view abstracts the underlying table, and users only need SELECT on the view. The error indicates a problem with the view owner's privileges, not the analyst's.
- ✓
The view owner does not have SELECT privilege on the underlying table, so the view cannot access it.
Why this is correct
In Unity Catalog, views run with the view owner's privileges. If the owner lacks SELECT on the base table, the view cannot retrieve data, causing an error for any user querying the view. The analyst's own privileges are irrelevant because the view executes as the owner. Thus, the owner must have the necessary privileges on the base table.
- ✗
The view is defined with SQL SECURITY INVOKER, which requires the analyst to have base table access.
Why it's wrong here
Unity Catalog does not support SQL SECURITY INVOKER for views; views always run with the owner's privileges. Therefore, this is not a valid configuration. The error is not due to invoker rights but likely due to the owner lacking base table privileges.
- ✗
The view was created without the SECURITY DEFINER clause, so the analyst's permissions are used to access the base table.
Why it's wrong here
In Unity Catalog, views are always executed with the view owner's permissions by default (definer's rights). There is no SECURITY DEFINER clause; that is a SQL Server concept. The error is not due to missing SECURITY DEFINER. The issue lies elsewhere, such as the view owner lacking privileges on the base table.
About these practice questions
One of 291 original Databricks-DA-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DA-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DA-Assoc exam.